Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

EC-Council · Free, ad-free audio course

EC-Council CCISO

A structured, audio-first learning route for EC-Council CCISO, designed for focused review and practical understanding.

Every Bare Metal Cyber audio course is free and 100% ad-free.

Companion Books

Study with the audio course, then reinforce it in print.

The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

70 lessons available

S01E01Transcript

Getting Started

Welcome to the CCISO Certification

In this opening episode of The Bare Metal Cyber CCISO Prepcast, we lay the foundation for your journey to becoming a Certified Chief Information Security Officer.…

Transcript availableJuly 6, 2025
S01E02Transcript

Getting Started

CCISO Exam Structure, Domains, and Cognitive Levels

This episode takes a deep dive into the anatomy of the CCISO exam itself. We explain how the exam is structured, how many questions you’ll encounter, what format those questions take, and how EC-Council assesses the executive-level thinking required for certification.…

Transcript availableJuly 6, 2025
S01E03Transcript

Getting Started

CCISO Exam Eligibility and Experience Requirements

Before registering for the CCISO exam, it’s crucial to understand EC-Council’s eligibility rules—and in this episode, we walk you through every requirement. The CCISO isn’t a certification you can simply purchase and attempt.…

Transcript availableJuly 6, 2025
S01E05Transcript

Getting Started

Key Acronyms and Terminology for the CCISO Exam

Before diving into heavy strategy and technical content, this episode gives you a valuable head start by covering the most critical acronyms, standards, and terms that will appear throughout the CCISO curriculum and the exam itself.…

Transcript availableJuly 6, 2025
S01E06Transcript

Getting Started

Proven Exam-Day Tips and Time Management Strategies

In this high-impact episode, we focus on strategies that can make or break your CCISO exam performance. It’s not just about what you know—it’s about how you manage your time, your confidence, and your cognitive stamina under pressure.…

Transcript availableJuly 6, 2025
S01E07Transcript

Governance and Risk Management

Information Security Governance Basics

This episode marks the beginning of Domain 1, and we start with the fundamental principles of information security governance.…

Transcript availableJuly 6, 2025
S01E08Transcript

Governance and Risk Management

Organizational Structures in Information Security

In this episode, we analyze how information security is positioned within different organizational structures and why that matters to the CCISO role. We discuss the various models—centralized, decentralized, matrixed—and the unique strengths and weaknesses of each.…

Transcript availableJuly 6, 2025
S01E09Transcript

Governance and Risk Management

Information Security Roles and Responsibilities

Who does what in the security hierarchy—and how do those roles contribute to governance, risk, and compliance outcomes? This episode answers that question by mapping the key roles involved in information security management, from security analysts to C-suite executives.…

Transcript availableJuly 6, 2025
S01E10Transcript

Governance and Risk Management

Risk Management Fundamentals

Listen to Risk Management Fundamentals in the EC-Council CCISO audio course.

Transcript availableJuly 6, 2025
S01E11Transcript

Governance and Risk Management

ISO 27005 Risk Assessment Essentials

In this episode, we explore ISO/IEC 27005, the international standard that provides guidelines for information security risk management.…

Transcript availableJuly 6, 2025
S01E12Transcript

Governance and Risk Management

NIST RMF Essentials for Executives

This episode introduces the NIST Risk Management Framework (RMF) from an executive perspective, highlighting how it applies to both federal and private sector environments.…

Transcript availableJuly 6, 2025
S01E13Transcript

Governance and Risk Management

FAIR Quantitative Risk Management Overview

Quantifying risk in financial terms is a vital executive skill, and this episode introduces the FAIR (Factor Analysis of Information Risk) framework to help you build that capability.…

Transcript availableJuly 6, 2025
S01E14Transcript

Governance and Risk Management

Compliance Essentials for CISOs

Compliance is more than just following rules—it’s about designing sustainable programs that meet regulatory expectations while supporting business objectives.…

Transcript availableJuly 6, 2025
S01E15Transcript

Governance and Risk Management

Legal and Regulatory Requirements

In this episode, we explore the legal landscape that CISOs must navigate when managing information security programs. You’ll learn about the growing body of national and international laws that shape data protection, breach notification, privacy obligations, and due diligence.…

Transcript availableJuly 6, 2025
S01E16Transcript

Governance and Risk Management

GDPR Essentials for CISOs

This episode focuses on the General Data Protection Regulation (GDPR) and what CISOs must understand about it to lead global privacy programs effectively.…

Transcript availableJuly 6, 2025
S01E17Transcript

Governance and Risk Management

Information Security Policy Development

Effective policy is the backbone of a sound security governance program. In this episode, we break down the entire lifecycle of policy development—from initial scoping and stakeholder input to review, approval, communication, and enforcement.…

Transcript availableJuly 6, 2025
S01E18Transcript

Governance and Risk Management

Framework Alignment Strategies

In this strategy-focused episode, we guide you through aligning your security program with one or more established control frameworks.…

Transcript availableJuly 6, 2025
S01E19Transcript

Governance and Risk Management

Auditing Security Governance

Audit plays a vital role in validating that security governance structures are functioning as intended—and this episode teaches you how to prepare for, support, and learn from internal and external audits.…

Transcript availableJuly 6, 2025
S01E20Transcript

Governance and Risk Management

Third-Party and Vendor Risk Management

Vendors can introduce significant security risks into your organization—and in this episode, we explain how CISOs assess, monitor, and manage those risks at scale.…

Transcript availableJuly 6, 2025
S01E21Transcript

Security Controls and Audit Management

Introduction to Security Controls

This episode introduces the foundational concept of security controls and explains their critical role in any enterprise cybersecurity program. You’ll learn how controls are used to mitigate risk, enforce policy, and align security with business needs.…

Transcript availableJuly 6, 2025
S01E22Transcript

Security Controls and Audit Management

Designing Effective Security Controls

Designing security controls isn’t just about selecting tools—it’s about architecting defenses that support business operations while addressing real threats.…

Transcript availableJuly 6, 2025
S01E23Transcript

Security Controls and Audit Management

Implementing Security Controls

Once controls are designed, the implementation phase is where strategy meets execution—and where leadership challenges often emerge.…

Transcript availableJuly 6, 2025
S01E24Transcript

Security Controls and Audit Management

Measuring and Evaluating Control Effectiveness

After implementation, CISOs must continuously assess whether security controls are actually doing their job. This episode dives into the methodologies and metrics used to evaluate control effectiveness over time.…

Transcript availableJuly 6, 2025
S01E25Transcript

Security Controls and Audit Management

Compliance Auditing Standards and Frameworks

In this episode, we take a comprehensive look at the major compliance standards and audit frameworks that govern information security practices across industries and geographies.…

Transcript availableJuly 6, 2025
S01E26Transcript

Security Controls and Audit Management

Internal Audit Process Fundamentals

This episode breaks down the internal audit process from the perspective of a security executive. You’ll learn how internal audits are used to evaluate control effectiveness, assess risk posture, and provide assurance to executive leadership and the board.…

Transcript availableJuly 6, 2025
S01E27Transcript

Security Controls and Audit Management

External Audit Preparation

Unlike internal audits, external audits are driven by third parties, regulators, or clients—and come with heightened stakes and external visibility.…

Transcript availableJuly 6, 2025
S01E28Transcript

Security Controls and Audit Management

Responding to and Managing Audit Findings

Once an audit is complete, the focus shifts to interpreting and responding to findings—a process that can significantly impact your credibility and the organization’s risk exposure.…

Transcript availableJuly 6, 2025
S01E29Transcript

Security Controls and Audit Management

Reporting Audit Outcomes

Audit outcomes aren’t just internal affairs—they often need to be communicated to boards, regulators, and third-party partners. This episode focuses on how CISOs summarize and report audit results in ways that are both accurate and strategically positioned.…

Transcript availableJuly 6, 2025
S01E30Transcript

Security Controls and Audit Management

Metrics and KPIs for Security Controls

Security metrics and key performance indicators (KPIs) are critical tools for evaluating the effectiveness of your security program. In this episode, we explain how to design, collect, and interpret meaningful metrics that tie directly to risk, compliance, and business impact.…

Transcript availableJuly 7, 2025
S01E31Transcript

Security Controls and Audit Management

Security Controls Lifecycle Management

Security controls are not set-and-forget tools—they require ongoing oversight to remain effective.…

Transcript availableJuly 7, 2025
S01E32Transcript

Security Controls and Audit Management

Continuous Monitoring of Security Controls

Continuous monitoring is the mechanism by which CISOs stay ahead of threats, vulnerabilities, and operational failures. In this episode, we unpack what it means to implement and sustain continuous monitoring programs at the enterprise level.…

Transcript availableJuly 7, 2025
S01E33Transcript

Security Controls and Audit Management

Executive Audit Management

Executive engagement in audits requires more than just approvals—it involves setting expectations, directing focus, and shaping outcomes.…

Transcript availableJuly 7, 2025
S01E34Transcript

Security Program Management and Operations

Crafting an Effective Security Program Charter

Every successful security program begins with a strong charter—a formal document that defines the mission, scope, authority, and governance model for your cybersecurity initiative.…

Transcript availableJuly 7, 2025
S01E35Transcript

Security Program Management and Operations

Creating a Security Roadmap

Once your charter is established, the next step is creating a security roadmap that charts a clear path forward. In this episode, we explain how CISOs build strategic plans that balance short-term priorities with long-term goals.…

Transcript availableJuly 7, 2025
S01E36Transcript

Security Program Management and Operations

Budgeting Fundamentals: Planning and Strategy

In this episode, we explore the financial planning responsibilities that fall on every CCISO, starting with the fundamentals of budgeting.…

Transcript availableJuly 7, 2025
S01E37Transcript

Security Program Management and Operations

Resource Allocation Strategies for Security Leaders

Security leaders must do more than secure funding—they must make smart, defensible decisions about how to allocate people, tools, and time.…

Transcript availableJuly 7, 2025
S01E38Transcript

Security Program Management and Operations

Building Effective Security Teams

No security program can succeed without a well-structured, skilled, and motivated team. In this episode, we cover how CISOs build and lead security teams that are aligned to both technical and organizational goals.…

Transcript availableJuly 7, 2025
S01E39Transcript

Security Program Management and Operations

Incident Management Basics

Every security leader must be prepared to lead during a crisis—and that begins with mastering the fundamentals of incident management. In this episode, we walk through the full lifecycle of incident handling, from detection and triage to containment, eradication, and recovery.…

Transcript availableJuly 7, 2025
S01E40Transcript

Security Program Management and Operations

Advanced Incident Response Techniques

Once the basics of incident management are in place, advanced techniques are needed to handle complex, multi-phase, or high-stakes threats.…

Transcript availableJuly 7, 2025
S01E41Transcript

Security Program Management and Operations

Digital Forensics Essentials for Executives

Digital forensics is no longer just a technical specialty—it’s an executive concern that intersects with legal risk, regulatory obligations, and organizational reputation.…

Transcript availableJuly 7, 2025
S01E42Transcript

Security Program Management and Operations

Business Continuity Planning Fundamentals

Business continuity planning (BCP) ensures that critical operations can continue even in the face of major disruptions—and CISOs play a central role in shaping those plans.…

Transcript availableJuly 7, 2025
S01E43Transcript

Security Program Management and Operations

Disaster Recovery Strategy Essentials

Disaster recovery (DR) is the technical counterpart to business continuity—and this episode explores how CISOs ensure the restoration of systems, services, and data after catastrophic disruptions.…

Transcript availableJuly 7, 2025
S01E44Transcript

Security Program Management and Operations

Security Operations Center (SOC) Basics

The Security Operations Center, or SOC, is the front line of defense against cyber threats. In this episode, we explain how SOCs operate, what core functions they perform, and how they fit into an enterprise security architecture.…

Transcript availableJuly 7, 2025
S01E45Transcript

Security Program Management and Operations

Leveraging SIEM Solutions Strategically

Security Information and Event Management (SIEM) platforms are powerful tools for correlation, alerting, and visibility—but they can also become operational burdens if poorly managed.…

Transcript availableJuly 7, 2025
S01E46Transcript

Security Program Management and Operations

Vulnerability Management Essentials

Vulnerability management is the process of identifying, evaluating, and remediating weaknesses in systems, applications, and configurations before they can be exploited.…

Transcript availableJuly 7, 2025
S01E47Transcript

Security Program Management and Operations

Threat Intelligence for Executives

Listen to Threat Intelligence for Executives in the EC-Council CCISO audio course.

Transcript availableJuly 7, 2025
S01E48Transcript

Security Program Management and Operations

Threat Hunting Basics for Executives

Threat hunting goes beyond traditional alert-driven detection by proactively searching for indicators of compromise within the environment. In this episode, we explore what threat hunting is, why it's becoming a critical capability, and how CISOs support and guide hunting programs.…

Transcript availableJuly 7, 2025
S01E49Transcript

Security Program Management and Operations

Advanced Threat Hunting Concepts

Building on the previous episode, we now explore more advanced threat hunting concepts that CISOs must understand to support elite detection capabilities.…

Transcript availableJuly 7, 2025
S01E50Transcript

Information Security Core Competencies

Access Control Models Overview

Access control is foundational to every security program, and this episode introduces the core models used to govern who can access what, when, and under what conditions.…

Transcript availableJuly 7, 2025
S01E51Transcript

Information Security Core Competencies

Best Practices for Access Control

Once you've selected the right access control model, the challenge shifts to enforcing it consistently across systems, users, and environments. In this episode, we walk through best practices for implementing, maintaining, and auditing access control systems in complex enterprises.…

Transcript availableJuly 7, 2025
S01E52Transcript

Information Security Core Competencies

Endpoint Security Essentials

Endpoints represent one of the largest attack surfaces in modern organizations, making endpoint protection a critical priority.…

Transcript availableJuly 7, 2025
S01E53Transcript

Information Security Core Competencies

Network Security for Executives

Network security remains a foundational element of cybersecurity architecture, even as perimeter boundaries blur in cloud-first and remote-enabled environments.…

Transcript availableJuly 7, 2025
S01E54Transcript

Information Security Core Competencies

Cloud Security Fundamentals

As organizations migrate more infrastructure and services to the cloud, CISOs must adapt their strategies to manage risk in cloud environments.…

Transcript availableJuly 7, 2025
S01E55Transcript

Information Security Core Competencies

Data Security and Privacy Basics

Data is the crown jewel of most organizations—and protecting it is a central responsibility of the CISO.…

Transcript availableJuly 7, 2025
S01E56Transcript

Information Security Core Competencies

Encryption Principles and Practices

Encryption is a cornerstone of data protection, and in this episode, we break down its role in securing data both at rest and in transit.…

Transcript availableJuly 7, 2025
S01E57Transcript

Information Security Core Competencies

Physical Security Management

While cybersecurity often dominates the conversation, physical security remains an essential component of any comprehensive security program.…

Transcript availableJuly 7, 2025
S01E58Transcript

Information Security Core Competencies

Mobile Device Security Essentials

With mobile devices becoming core tools for business productivity, they also represent a growing attack surface that CISOs must manage. In this episode, we examine the risks posed by smartphones, tablets, and other portable devices, and the controls needed to secure them.…

Transcript availableJuly 7, 2025
S01E59Transcript

Information Security Core Competencies

Virtualization Security Overview

Virtualized environments introduce a unique set of security concerns that CISOs must understand and manage. In this episode, we break down how hypervisors, virtual machines, and containers work—and how these technologies change the security landscape.…

Transcript availableJuly 7, 2025
S01E60Transcript

Information Security Core Competencies

Emerging Tech in Security: AI and Machine Learning

Artificial intelligence and machine learning are rapidly reshaping the cybersecurity landscape—and CISOs must understand both their potential and their limitations.…

Transcript availableJuly 7, 2025
S01E62Transcript

Strategic Planning, Finance and Procurement

Aligning Security with Organizational Objectives

Security is no longer a siloed function—it must be embedded in business strategy. In this episode, we examine how CISOs align cybersecurity initiatives with overarching organizational goals.…

Transcript availableJuly 7, 2025
S01E63Transcript

Strategic Planning, Finance and Procurement

Strategic Security Planning Frameworks (TOGAF, SABSA)

Effective security leaders think in frameworks—and in this episode, we explore two of the most influential planning models for enterprise architecture: TOGAF (The Open Group Architecture Framework) and SABSA (Sherwood Applied Business Security Architecture).…

Transcript availableJuly 7, 2025
S01E64Transcript

Strategic Planning, Finance and Procurement

Financial Management Principles for Security Leaders

Financial fluency is essential for every CISO—and in this episode, we break down the core principles of financial management in the context of enterprise cybersecurity.…

Transcript availableJuly 7, 2025
S01E65Transcript

Strategic Planning, Finance and Procurement

Security Budgeting Essentials: Managing and Adjusting Budgets

Security budgeting doesn’t end once funding is approved—CISOs must continuously manage, adjust, and defend their budgets in the face of shifting priorities and evolving threats.…

Transcript availableJuly 7, 2025
S01E66Transcript

Strategic Planning, Finance and Procurement

ROI and Cost-Benefit Analysis for Security Investments

As cybersecurity budgets grow, so does the need to justify investments with clear, measurable value. In this episode, we explore how CISOs evaluate the return on investment (ROI) of security initiatives, technologies, and services.…

Transcript availableJuly 7, 2025
S01E68Transcript

Strategic Planning, Finance and Procurement

Vendor Contracts, SLAs, and Performance Metrics

Securing a vendor is only the beginning—the real work lies in managing performance, risk, and accountability.…

Transcript availableJuly 7, 2025
S01E69Transcript

Strategic Planning, Finance and Procurement

Vendor Risk Oversight and Auditing

Vendor relationships introduce risk far beyond basic performance metrics—and in this episode, we dive into the executive oversight practices required to manage those risks.…

Transcript availableJuly 7, 2025
S01E70Transcript

Exam Strategy and Review

Final Exam Review and Strategy

In this final episode of the prepcast, we shift focus from content to performance. You’ve learned the material—now it's time to master the test. We walk through proven strategies for final review, including how to prioritize domains, balance study time, and simulate test conditions.…

Transcript availableJuly 7, 2025

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.

03

Review

Use the flashcards book to practice active recall and quickly revisit weak areas.